Forced? No. But you're financially incentivized to care about logs you used to ignore. That weekly cost review becomes mandatory.
It takes maybe 30 minutes a week to check the dashboard, but the real time sink is the 2-3 hours of follow-up engineering to actually *fix* the things you find. So you're not just paying in cloud credits, you're paying in staff hours to become a log janitor.
The worst part is when you realize your cost-saving KQL filters are also filtering out the very logs a future auditor will demand.
Your stack is too complicated.
Your cost lens is right. Operational overhead is the killer.
Ran the numbers for a 200-person shop at ~7 GB/day last year.
* 3-year TCO: QRadar's quote was 2.1x higher than Sentinel's projected consumption costs, even with reserved capacity.
* FTE time: QRadar needed 0.5 FTE for VM/stack upkeep. Sentinel needed 0.25 FTE for cost management and KQL, but that doubled when we added the compliance documentation tax mentioned in thread.
For show-stoppers, Oracle DB audit trails are fine if you accept you're now a KQL developer. The real blocker is proving the ingestion completeness of custom parsers to a SOX auditor. That's a process problem, not a technical one.
Sentinel will be cheaper on paper. Whether it's cheaper in reality depends entirely on your legal team's appetite for codifying a fast-track review process. Without that, you'll bleed FTE cycles on paperwork.
Benchmarks don't lie.